Skip to content

spec: seed the 4.2 candidate with the slot-disposition scoping (#42) - #70

Merged
Nicholas-Keystate merged 2 commits into
Nicholas-Keystate:mainfrom
dhh1128:spec/4.2-seed-slot-disposition
Aug 8, 2026
Merged

spec: seed the 4.2 candidate with the slot-disposition scoping (#42)#70
Nicholas-Keystate merged 2 commits into
Nicholas-Keystate:mainfrom
dhh1128:spec/4.2-seed-slot-disposition

Conversation

@dhh1128

@dhh1128 dhh1128 commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Seeds the 4.2 candidate with a repair for finding #42. No ratified bytes are altered — this adds one unpinned seed document under spec/, in the shape PR #26 established. tools/verify_kernel.py passes 6/6.

Addresses #42 without closing it. Repair 1 is in the ratified edition (§9, census round 42-6, CONVERGED); repair 2 — the slot's disposition on each pending requirement element — is not, and the census records it as F-6 with the encoding round as its plausible home. Closing #42 on this merge would discharge half the finding and lose the other half's trace, so the keyword is demoted and #42 closes when the residual is dispositioned.

Executed under adjudication S3-1 of supplement 3. When this PR opened, #42 carried no ruling. It has one now: the integration round's outside leg reached the same sentence independently as its finding A12, ruled it BLOCKING false generality, the same-family leg cited the same site as a model, and S3-1 adjudicated the round's only true fork by scoping the claim to analogous constructions. The seed is updated to the ruling's vocabulary and shape.

What section 8 claims, and what transfers

§8 (4.1 L1256–1262) says the threshold algebra is one algebra at both ends of the system, "so a verifier that can evaluate a rotation can evaluate a quorum of endorsements (a derivation from the substrate's design, not new law)."

The algebra does transfer, and the dossier specification says so in its own words: the weighted threshold is "the same fractionally weighted threshold KERI uses for key-event signing thresholds (kt)".

The satisfaction predicate does not transfer, and it is everything that decides what enters the sum. The substrate's threshold evaluator takes a list of indices of verified signatures. A dossier slot counts as Endorsed only when it references a signed endorsement ACDC with disposition endorse and an appropriate act, from the expected endorser, anchored in that endorser's KEL, with said equal to the dossier SAID — plus, for the qualified operators, a qualification proof validating against the schema the operator's qs field names.

A key-list offset versus a cross-log walk. The seed scopes the sentence to the algebra and adds a SHALL NOT: an implementation may not treat the substrate's threshold evaluator as discharging §8's composed-evidence obligation.

The clause underneath it was incomplete for the same reason

L1262–1267 discharges an unsatisfied group as a pending finding "whose typed requirement set enumerates exactly the unfilled slots". The cited grammar has no such state. It has three: Pending (an anticipated endorsement that has not arrived), Endorsed, and Declined (an authenticated refusal by the same candidate, recording attributable dissent).

"Unfilled" collapses Pending and Declined, and they have opposite cure paths — a pending slot is cured by the candidate acting, a declined slot is never cured by waiting. The replacement names the disposition as a fourth component of each requirement element, and cites the vocabulary rather than transcribing it, since R20 already makes the dossier threshold semantics a pinned external dependency where used.

What stays open

The species mapping. §7.2 makes species a mandatory field, and R3 puts it in the dedup key and as the final component of the canonical order — so species is load-bearing for the byte-identity SHALL at L1037–1038. Nothing says which species a slot disposition maps to. Pending is plausibly absent; Declined is plainly not, because the bytes arrived and are authenticated. Two engines choosing differently emit requirement sets differing in a key component. That is finding #27's divergence class one tier up, and #27 resolved by ruling rather than by drafting, so this seed flags it and does not choose.

The exercising fixture. #15's conformance-vector work. A three-slot group with one endorsed, one pending and one declined slot is the record that separates an engine holding the predicate from one holding only the arithmetic. §14 makes the unexercised claim a defect of this document "reviewable as such", so the narrowing is the interim and the fixture is the discharge.

What S3-1 added, and one caution

The replacement now says analogous constructions — one satisfaction shape over slot judgments of different kinds — with the slot judgment named as this document's own fold question rather than the substrate's. It also carries S3-1's forward clause: once the shared satisfaction predicate exists as its own committed artifact upstream, both sites cite it by digest and the analogy becomes a declared shared dependency by ordinary migration, with no re-ruling owed. The translation profile — slot order, issuer qualification, revoked and undisclosed slot behavior — routes to the encoding round per the same adjudication.

One caution for the drafting pass. S3-1's parenthetical observes that the reference implementation evaluates both ends with one class. That describes a shape, not an exercised path: as of WebOfTrust/keripy @ c63726654 no m-ary or threshold edge-group operator exists under src/keri, and the only edge-operator logic is the unary set. The candidate should state the coincidence of shape without implying one evaluator has been run against both kinds of slot, which is the overclaim the repair removes.

Verification

Re-read 2026-08-05 against trustoverip/kswg-dossier-specification @ 3900e62 and WebOfTrust/keripy @ c63726654. Both are later than the revisions the engagement companion records for the 4.1 engagement surface (dossier c2d261c, keripy 8e67f2e); the substance is unchanged across the interval, and the seed says so rather than implying it read the pins.

The finding's own line-number citations into the dossier spec have drifted since 2026-07-30 — the claims are all still there, under section headings rather than at the cited offsets. Every citation in the seed is therefore by section name and quoted phrase. That is R20's argument arriving uninvited: the semantics did not move, the coordinates did, and only one of those survives a replay.

…las-Keystate#42)

Section 8 claims a verifier that can evaluate a rotation can evaluate a
quorum of endorsements. The threshold algebra does transfer; the
satisfaction predicate does not - at the key tier a slot is filled by a
verified signature at a key-list offset, at the evidence tier by a
cross-log check on a committed endorsement. The seed scopes the claim to
the algebra and completes the pending-discharge clause beneath it, which
says 'unfilled slots' where the cited grammar has three dispositions and
a declined slot is never cured by waiting.

It also records what neither repair closes: which section 7.2 species a
slot disposition maps to is unstated, and under R3 species is a
component of the canonical order, so the mapping is a byte-identity
exposure of finding Nicholas-Keystate#27's class.

Signed-off-by: Daniel Hardman <daniel.hardman@gmail.com>
@dhh1128
dhh1128 marked this pull request as draft August 5, 2026 04:00
Supplement 3 adjudicates the same sentence this seed repairs, after the
integration round's two legs reached opposite verdicts on it and the
authority scoped the claim to analogous constructions. The replacement
adopts the ruling's word and its shape: one satisfaction shape over slot
judgments of different kinds, the slot judgment named as this document's
own fold question, and the forward clause that upgrades the analogy to a
declared shared dependency by ordinary migration once the shared
predicate exists upstream. The translation profile routes to the
encoding round.

Also records a factual caution the adjudication's parenthetical could
obscure: the reference implementation's one-class observation describes a
shape, not an exercised path - no m-ary or threshold edge-group operator
exists under src/keri at c63726654 - which is the overclaim this repair
removes.

Signed-off-by: Daniel Hardman <daniel.hardman@gmail.com>
@dhh1128
dhh1128 marked this pull request as ready for review August 5, 2026 19:56
@dhh1128

dhh1128 commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator Author

S3-1 absorbed — be966e1. Out of draft, and Closes #42 is back on.

This opened as a draft because #42 carried no ruling. Supplement 3 changed that from an unexpected direction: the integration round's outside leg reached the same sentence independently as its A12, ruled it BLOCKING false generality, the same-family leg listed the same site as a model citation, and S3-1 adjudicated what the collation calls the round's only true fork.

The seed now speaks the ruling's vocabulary. The replacement says analogous constructions — one satisfaction shape over slot judgments of different kinds — with the slot judgment named as this document's own fold question rather than the substrate's, and it carries S3-1's forward clause: once the shared satisfaction predicate exists as its own committed artifact upstream, both sites cite it by digest and the analogy becomes a declared shared dependency by ordinary migration, no re-ruling owed. The translation profile routes to the encoding round.

The seed's earlier phrasing — the algebra transfers, the predicate does not — is the same claim in vocabulary the candidate doesn't use. That's recorded rather than quietly swapped, since the difference between the two legs was a difference of grain and the word is what carries it.

One caution I'd rather state than leave implied. S3-1's parenthetical observes that the reference implementation evaluates both ends with one class. That describes a shape, not an exercised path: as of WebOfTrust/keripy @ c63726654 there is no m-ary or threshold edge-group operator under src/keri, and the only edge-operator logic is the unary set at verifying.py:360. The candidate should state the coincidence of shape without implying one evaluator has been run against both kinds of slot — that implication is the overclaim the repair exists to remove.

The vector S3-1's station obligation assigns is V-S31-01 in PR #72's ledger: an edge slot fed to a signing-threshold evaluator with no standing appraisal, expected to diverge from the ruled reading.

@Nicholas-Keystate Nicholas-Keystate mentioned this pull request Aug 7, 2026
@Nicholas-Keystate

Copy link
Copy Markdown
Owner

Reconciliation census (42-6): CONVERGED with one flagged component — merge-as-record, plus one docket item. The S3-1 absorption is sound (the seed's 'analogous constructions' matches the ratified sentence). The flag: your repair 2 (the slot Pending/Declined disposition) is NOT in the ratified §9's 'unfilled slots' treatment — census finding F-6, routed to the carriage-encoding round (#57) so it isn't lost. Recommend a pointer from this PR's description to that docket entry on merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants